CHP Safety & Infection Control 3 — Questions and Answers
Question 1: During a public health emergency involving an infectious disease outbreak, a covered entity wants to share patient PHI with public health authorities without patient authorization. Which HIPAA provision permits this?
- The Minimum Necessary Rule waives all restrictions during emergencies
- The Public Health Activities exception allows disclosure to public health authorities authorized by law to collect data (Correct answer)
- PHI may never be disclosed without patient authorization regardless of circumstances
- Only de-identified data may be shared with public health authorities
Correct answer: The Public Health Activities exception allows disclosure to public health authorities authorized by law to collect data
HIPAA's Public Health Activities exception (45 CFR § 164.512(b)) permits covered entities to disclose PHI to authorized public health authorities for activities such as disease surveillance and outbreak response.
Question 2: A nurse accidentally sticks herself with a needle used on an HIV-positive patient. The hospital's occupational health team requests the patient's HIV status. What does HIPAA permit in this scenario?
- The patient's HIV status may never be shared without written authorization
- HIPAA permits disclosure of the patient's HIV status to the source patient's treating provider and the exposed worker's healthcare provider for treatment purposes (Correct answer)
- The hospital must obtain a court order before accessing the patient's HIV status
- The nurse must file a formal complaint with the Office for Civil Rights before access is granted
Correct answer: HIPAA permits disclosure of the patient's HIV status to the source patient's treating provider and the exposed worker's healthcare provider for treatment purposes
HIPAA's treatment exception and workforce safety provisions allow disclosure of the source patient's relevant PHI to facilitate occupational exposure management.
Question 3: Which OSHA standard works in conjunction with HIPAA to protect healthcare workers from bloodborne pathogen exposure risks?
- OSHA Hazard Communication Standard (HazCom)
- OSHA Bloodborne Pathogens Standard (29 CFR 1910.1030) (Correct answer)
- OSHA Personal Protective Equipment Standard (29 CFR 1910.132)
- OSHA Respiratory Protection Standard (29 CFR 1910.134)
Correct answer: OSHA Bloodborne Pathogens Standard (29 CFR 1910.1030)
OSHA's Bloodborne Pathogens Standard requires employers to protect workers from exposure to blood and other potentially infectious materials, complementing HIPAA's privacy protections for patient information related to these exposures.
Question 4: A covered entity's security policy requires that all workstations be logged off or locked when unattended. This requirement primarily addresses which HIPAA Security Rule implementation specification?
- Contingency Plan
- Automatic Logoff (Correct answer)
- Integrity Controls
- Transmission Security
Correct answer: Automatic Logoff
The Automatic Logoff implementation specification (addressable) under the Access Control standard requires entities to implement electronic procedures that terminate sessions after a predetermined period of inactivity.
Question 5: A hospital emergency department uses a shared 'break-the-glass' override procedure to access ePHI during a mass casualty event. Under HIPAA, this is best characterized as:
- A HIPAA violation because all access must be pre-authorized
- A permissible emergency access procedure that must be documented and reviewed after the event (Correct answer)
- A practice that requires prior HHS approval each time it is used
- An acceptable practice only if the patients involved later provide written consent
Correct answer: A permissible emergency access procedure that must be documented and reviewed after the event
HIPAA permits emergency access procedures and requires covered entities to establish them; however, all emergency access events must be logged and reviewed to detect inappropriate use.
Question 6: Which practice BEST supports both infection control and HIPAA compliance when healthcare staff use mobile devices to document patient care?
- Allowing staff to use any personal device without restriction to maximize convenience
- Implementing a mobile device management (MDM) solution with remote wipe, encryption, and device hygiene guidelines (Correct answer)
- Prohibiting all mobile device use in clinical areas regardless of operational need
- Requiring patients to sign a waiver acknowledging that mobile devices may transmit their PHI
Correct answer: Implementing a mobile device management (MDM) solution with remote wipe, encryption, and device hygiene guidelines
An MDM solution addresses HIPAA requirements for encryption, access control, and remote wipe while device hygiene guidelines address infection control concerns in clinical environments.
Question 7: Under HIPAA, when a covered entity discovers a breach involving PHI on paper records contaminated with biohazardous material, what is the CORRECT sequence of priorities?
- Notify affected individuals first, then safely dispose of contaminated records
- Safely contain and manage the biohazard following infection control protocols, then conduct breach analysis and notifications per HIPAA Breach Notification Rule (Correct answer)
- Immediately scan and digitize the contaminated records before safe disposal
- Report the incident to law enforcement before taking any other action
Correct answer: Safely contain and manage the biohazard following infection control protocols, then conduct breach analysis and notifications per HIPAA Breach Notification Rule
Life safety and infection control always take precedence; once the biohazard is controlled, the organization must conduct a breach risk assessment and follow the HIPAA Breach Notification Rule timeline.
During a public health emergency involving an infectious disease outbreak, a covered entity wants to share patient PHI with public health authorities without patient authorization.
Which HIPAA provision permits this?